CVE-2024-20036

In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*

History

22 Apr 2025, 20:23

Type Values Removed Values Added
First Time Mediatek
Mediatek mt8796
Mediatek mt8798
Mediatek mt6886
Mediatek mt6855
Mediatek mt6895
Mediatek mt6983
Mediatek mt6835
Mediatek mt6985
Mediatek mt8792
Google android
Mediatek mt6879
Google
CPE cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:*
References () https://corp.mediatek.com/product-security-bulletin/March-2024 - () https://corp.mediatek.com/product-security-bulletin/March-2024 - Vendor Advisory

20 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-284

21 Nov 2024, 08:51

Type Values Removed Values Added
References () https://corp.mediatek.com/product-security-bulletin/March-2024 - () https://corp.mediatek.com/product-security-bulletin/March-2024 -

26 Aug 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.4
Summary
  • (es) En vdec, existe una posible omisión de permisos debido a una omisión de permisos. Esto podría conducir a la divulgación de información local con privilegios de ejecución de System necesarios. La interacción del usuario no es necesaria para la explotación. ID de parche: ALPS08509508; ID del problema: ALPS08509508.

04 Mar 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-04 03:15

Updated : 2025-04-22 20:23


NVD link : CVE-2024-20036

Mitre link : CVE-2024-20036

CVE.ORG link : CVE-2024-20036


JSON object : View

Products Affected

mediatek

  • mt6879
  • mt8796
  • mt6886
  • mt6855
  • mt8792
  • mt6985
  • mt8798
  • mt6895
  • mt6835
  • mt6983

google

  • android
CWE
CWE-284

Improper Access Control